CRITICAL · 9.8

CVE-2025-57437

The Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service on port 9977. When connected, the service reveals extensive device configuratio...

Vulnerability Description

The Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service on port 9977. When connected, the service reveals extensive device configuration data including: - Model, version, and unique identifiers - Network settings including IP, MAC, DNS - Current stream platform, stream key, and streaming URL - Audio/video configuration This data can be used to hijack live streams or perform network reconnaissance.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
BlackmagicdesignWeb Presenter Hd Firmware3.3
BlackmagicdesignWeb Presenter Hd-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-57437?

CVE-2025-57437 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service on port 9977. When connected, the service reveals extensive device configuratio...

How severe is CVE-2025-57437?

CVE-2025-57437 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2025-57437?

Check the references section above for vendor advisories and patch information. Affected products include: Blackmagicdesign Web Presenter Hd Firmware, Blackmagicdesign Web Presenter Hd.